Return to CVE list

CVE-2021-44659

9.8
Critical

CVE-2021-44659

cve@mitre.org
Modified

Description

Adding a new pipeline in GoCD server version 21.3.0 has a functionality that could be abused to do an un-intended action in order to achieve a Server Side Request Forgery (SSRF). NOTE: the vendor's position is that the observed behavior is not a vulnerability, because the product's design allows an admin to configure outbound requests

Exploits

No known exploits found for this CVE.

Search Exploit-DB

References

af854a3a-2127-422b-91ae-364da2661108
https://github.com/Mesh3l911/CVE-2021-44659
af854a3a-2127-422b-91ae-364da2661108
https://github.com/gocd/gocd
af854a3a-2127-422b-91ae-364da2661108
https://www.gocd.org/
af854a3a-2127-422b-91ae-364da2661108
https://youtu.be/WW_a3znugl0